Suspicious
Suspect

PE Executable
MD5: 51163f82695bced76fe66bd3ec1bd38a
Size: 837.12 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 51163f82695bced76fe66bd3ec1bd38a
Sha1 231aa25f74a5c8a0f8bd1944b71b47615a60d520
Sha256 29eeed93c836f8c75b109eae3ed94bd49fc2a7ea73928eb54bc3b296b6839f4f
Sha384 21a6a854bd4ade60815226944d4174fcb30c5e163093cae13e4eff27c035e9bbd0cbe3cda453cdfc612775bf1c1e55ec
Sha512 3e824fccd15c9228affb654c0595f283d6f20499b00f28833b01b533557a425d9aad834479cf04ee55e0f536a92f17011ee3bbac8f934ef5861ebcc5dca8ffaf
SSDeep 12288:pUOukNkV1eegREu/64ur8wMOw85RA4PHELoQrv7V63Jqbf+687dapHMJUmc1T29I:Dickt4uPw857PHELoQrBwaf+rNUmc5x
TLSH 2305BD3031AD9963DAB952F00460E13533AB6ECF282AD1D64DD6BDDB7CE4BC11B94A43
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
gsuH
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
Name Value
Module Name
ITOi.exe
Full Name
ITOi.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
ITOi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ITOi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
Module Name
ITOi.exe
Full Name
ITOi.exe
EntryPoint
System.Void QLDTDD_FPT.Program::Main()
Scope Name
ITOi.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
ITOi
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
975
Main Method
System.Void QLDTDD_FPT.Program::Main()
Main IL Instruction Count
6
Main IL
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
newobj System.Void QLDTDD_FPT.Mainform::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
ret <null>
PDB Path PATH
IThuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
QLDTDD_FPT.AM_Edit.resources
QLDTDD_FPT.Properties.Resources.resources
gsuH
[NBF]root.Data
[NBF]root.Data-preview.png
QLDTDD_FPT.StaffManagementForm.resources
$this.Icon
[NBF]root.IconData
kc
[NBF]root.Data
No malware configuration was found at this point.
PDB Path PATH
IThuhuhuhu
51163f82695bced76fe66bd3ec1bd38a
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙